Privilege Escalation Vulnerability in Keycloak by Red Hat
CVE-2026-3121
6.5MEDIUM
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 26 March 2026
What is CVE-2026-3121?
A misconfiguration within Keycloak could allow administrators with the 'manage-clients' permission to exploit this flaw, equating it mistakenly to 'manage-permissions'. This situation enables unauthorized privilege escalation, granting access to roles, users, and other critical administrative tasks within the realm, particularly when admin permissions are activated at the realm level.
Affected Version(s)
Red Hat build of Keycloak 26.4 26.4.11-1
Red Hat build of Keycloak 26.4 26.4-14
Red Hat build of Keycloak 26.4 26.4-14